Last updated: 10 June 2026 - DPDP Act 2023 + DPDP Rules 2025 aligned
Plain English summary: We collect only what we need to run your account, with your consent. We never sell your data or use it for advertising. Your clients' data belongs to your firm - we only store and process it on your instructions. You can withdraw consent, export, or delete everything at any time, as easily as you gave it.
Caledger is a product operated by Ledgerstack Technologies LLP ("we", "us"). Ledgerstack Technologies LLP is the Data Fiduciary for the personal data of registered account holders. Registered office: Bengaluru, Karnataka, India. For the client records your firm enters into Caledger, your firm is the Data Fiduciary and Ledgerstack Technologies LLP (through Caledger) acts as a Data Processor on your firm's instructions - we never use that data for our own purposes.
Collected: name, firm name, email address, WhatsApp number, city, plan and payment references, and a one-way hashed password.
Purpose: creating and operating your account, billing, sending account and security notifications, and support. We never store your password in readable form.
Stored: client names, GSTIN, contact details, filing statuses, notes.
Purpose: only to provide the service to your firm. This data is yours; we are the secure storage and processing layer.
Stored: the client's GST portal username and password, encrypted at rest with AES-256-GCM. The password is never returned to the browser, never displayed in any report, and never written to logs.
Purpose: solely to log in to the GST portal on that client's behalf to fetch their own filing status, returns and notices - the same task your firm would otherwise do manually. Credentials are decrypted only in server memory at the moment of a fetch, and every decryption is recorded in an access log. We store a credential only when your firm confirms it holds the client's authorisation to access their GST account; that confirmation is recorded with the staff member's name and the date. Your firm, as Data Fiduciary, is responsible for obtaining and retaining written authorisation from each client (an authorisation template is available on request).
Collected: name, email, phone and your message, with your explicit consent at the point of submission.
Purpose: responding to your enquiry. Not used for marketing without separate consent.
Collected: login times and security-relevant events.
Purpose: security monitoring, fraud prevention and legal compliance. Logs are retained for one year as required by the DPDP Rules, 2025. No advertising, profiling or tracking.
We process your personal data on the basis of the consent you give at signup or on a form, for the specific purposes stated there. You may withdraw consent at any time, with the same ease you gave it:
On withdrawal we stop processing and delete your personal data (see Retention below), except where retention is required by law. Withdrawal does not affect the lawfulness of processing already done.
On request, we will provide this notice in any language listed in the Eighth Schedule to the Constitution of India.
We respond to rights requests within 7 working days. If you are unsatisfied with our response, you have the right to complain to the Data Protection Board of India.
We do not sell, rent, or share personal data with any third party for their own use. Limited sharing happens only with:
In line with Rule 6 of the DPDP Rules, 2025: encryption in transit (TLS) everywhere, hashed credentials (bcrypt), strict access controls with per-firm isolation, encrypted recycle-bin storage, security logging with one-year retention, automated daily backups, and server-side rate limiting and intrusion protection. Core infrastructure and client data are hosted in India. A few operational sub-processors (captcha-solving, transactional email and web-push delivery) may process limited data outside India.
If a personal data breach affects you, we will inform you without delay in plain language - what happened, what data was involved, what we are doing, and what you can do - and report it to the Data Protection Board of India within the timelines prescribed by the DPDP Rules, 2025 (72 hours).
Caledger uses only essential cookies and local storage required for the application to function (session management, security tokens). No tracking cookies, no advertising cookies, no third-party analytics.
Grievance Officer: Himanshu Daga
Email: info@caledger.in
Address: Ledgerstack Technologies LLP, Bengaluru, Karnataka, India
We acknowledge grievances within 48 hours and resolve them within 7 working days. If unresolved, you may escalate to the Data Protection Board of India.
Caledger is a product operated by Ledgerstack Technologies LLP ("we", "us", "Caledger"). By creating an account on Caledger, you agree to these Terms of Service with Ledgerstack Technologies LLP. If you do not agree, do not use the service. These terms apply to all users - firm owners, CAs, and staff members.
Caledger is a practice management software for Indian CA firms. It provides client management, compliance tracking, staff management, and secure credential storage. Caledger is a tool to help you manage your practice - it does not provide legal, tax, or accounting advice.
You agree not to:
We aim for 99.5% uptime. Planned maintenance will be notified 24 hours in advance. We are not liable for losses resulting from downtime beyond our reasonable control.
Caledger is a practice management tool. We are not responsible for compliance failures, missed deadlines, or financial losses arising from use or non-use of the software. Users are responsible for verifying all compliance deadlines independently with official GSTN and Income Tax portals.
These terms are governed by the laws of India and constitute an agreement with Ledgerstack Technologies LLP. Any disputes shall be subject to the jurisdiction of courts in Bengaluru, Karnataka, India.
We may update these terms. We will notify you by email at least 14 days before material changes take effect. Continued use after that date constitutes acceptance.
✅ Short version: We offer a 7-day refund window from the date of first payment. Annual plans get a prorated refund within 30 days. Contact info@caledger.in to request a refund.
Payments for Caledger are collected by Ledgerstack Technologies LLP. If you are not satisfied within 7 days of your first payment, contact us at info@caledger.in and we will issue a full refund. No questions asked. Annual plans are eligible for a prorated refund within 30 days.
If you are not satisfied after your first payment on a monthly plan, contact us within 7 days of the payment date and we will refund the full amount - no questions asked.
After 7 days from payment, monthly plan payments are non-refundable. You can cancel anytime to stop future charges.
Annual plan payments are eligible for a prorated refund within 30 days of payment. After 30 days, annual plan payments are non-refundable but your access continues until the plan expiry date.
Email info@caledger.in with your firm name, registered email, and payment date. We process all refunds within 5 working days back to your original UPI account.
Our commitment: Your client data is treated with the same care an Indian bank applies to financial records. Here is exactly how we protect it.
Every query to our database includes a mandatory firm ID filter. It is technically impossible - not just policy - for one CA firm to access another firm's data. This is enforced at the database query level, not just the application level.
Within your firm, staff members only see clients assigned to them. Your admin/CA staff see all clients. This access control is enforced at every API endpoint.
When you save a GST portal password:
If you discover a security vulnerability, please report it responsibly to info@caledger.in with subject line "Security Report". We will acknowledge within 24 hours and aim to resolve critical issues within 72 hours. We do not pursue legal action against good-faith security researchers.